The repository has tests, a license file, matching package documentation, and organization backing. Its workflows use unpinned actions, lack security scanning, and show no recent maintenance, so pinning this release carries abandonment risk.
42%
Total Score
50
100
67
50
The package has had no release in over two years and no releases in the last 12 months; six releases were clustered on its first day, indicating stalled maintenance.
There were zero commits and zero active maintainers in the last three months, consistent with a project that has stopped receiving development attention.
The package runs a post-autoload-dump install-time script, adding execution during installation; this is a modest supply-chain hygiene concern but not evidence of abandonment by itself.
The repository has zero stars, forks, and watchers, providing no community adoption signal to offset the lack of recent activity.
Composer build tooling is present, but no security scanning tools were detected, leaving an avoidable security-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.